CVE-2022-2679: SourceCodester Interview Management System viewReport.php sql injection
A vulnerability was found in SourceCodester Interview Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /viewReport.php. The manipulation of the argument id with the input (UPDATEXML(9729,CONCAT(0x2e,0x716b707071,(SELECT (ELT(9729=9729,1))),0x7162766a71),7319)) leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-205667.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-2679?
CVE-2022-2679 has been rated as critical due to its potential impact on the affected system.
Which software versions are affected by CVE-2022-2679?
CVE-2022-2679 affects Interview Management System version 1.0.
How does the vulnerability CVE-2022-2679 operate?
CVE-2022-2679 exploits SQL injection through manipulation of the 'id' parameter in the /viewReport.php file.
How can I mitigate the risks associated with CVE-2022-2679?
To mitigate CVE-2022-2679, sanitize and validate user input to prevent SQL injection vulnerabilities.
Is there a fix available for CVE-2022-2679?
Currently, the fix for CVE-2022-2679 involves updating to a non-vulnerable version of the Interview Management System once available.